THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-70376 (CRITICAL 9.6) — Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

[NVD] CVE-2026-70376 (CRITICAL 9.6) — Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

mednvdPublished 2026-08-05

CVE-2026-70376 CVSS: 9.6 CRITICAL Published: 2026-08-05T08:16:41.703

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.php action) for CSRF protection, with no per-request anti-CSRF token anywhere in the admin area.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-70376